CVE-2026-72403

Source
https://cve.org/CVERecord?id=CVE-2026-72403
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72403.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72403
Downstream
Published
2026-08-15T05:56:27Z
Modified
2026-08-18T03:30:56Z
Summary
ALSA: FCP: Fix NULL pointer dereference in interface lookup
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: FCP: Fix NULL pointer dereference in interface lookup

A malformed USB device can provide a vendor-specific interface without any endpoint descriptors. fcp_find_fc_interface() currently selects the first vendor-specific interface and reads endpoint 0 from it, without checking whether the interface actually has any endpoints.

When bNumEndpoints is zero, no endpoint array is allocated for the parsed alternate setting, so get_endpoint(..., 0) yields an invalid endpoint descriptor pointer. Dereferencing it through usb_endpoint_num() then triggers a NULL pointer dereference.

Skip vendor-specific interfaces that do not have any endpoints.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72403.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
46757a3e7d50dac923888e7fbe68377736f13c70
Fixed
f28d7b5f1578a7501ab17b10643ed1e4f729187e
Fixed
3ab06151ffcb8c3aeb8f78508658b6c0f05be932
Fixed
e1e31e0ec8a609e17fd2e86b77bc00d9cbb24d7c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72403.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.14.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72403.json"